WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin 存在SQL注入漏洞,该漏洞源于WP_查询中的不正确清理。攻击者可利用该漏洞执行SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WordPress | wordpress-develop | < 5.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Core 5.8.2 - 'WP_Query' SQL Injection | https://github.com/TAPESH-TEAM/CVE-2022-21661-WordPress-Core-5.8.2-WP_Query-SQL-Injection | POC Details |
| 2 | None | https://github.com/purple-WL/wordpress-CVE-2022-21661 | POC Details |
| 3 | Wordpress 5.8.2 CVE-2022-21661 Vuln enviroment POC exploit | https://github.com/0x4E0x650x6F/Wordpress-cve-CVE-2022-21661 | POC Details |
| 4 | WordPress WP_Query SQL Injection POC | https://github.com/z92g/CVE-2022-21661 | POC Details |
| 5 | CVE-2022-21661 exp for Elementor custom skin. | https://github.com/QWERTYisme/CVE-2022-21661 | POC Details |
| 6 | The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661) | https://github.com/APTIRAN/CVE-2022-21661 | POC Details |
| 7 | Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3. | https://github.com/WellingtonEspindula/SSI-CVE-2022-21661 | POC Details |
| 8 | Demonstration of the SQL injection vulnerability in wordpress 5.8.2 | https://github.com/daniel616/CVE-2022-21661-Demo | POC Details |
| 9 | A Python PoC of CVE-2022-21661, inspired from z92g's Go PoC | https://github.com/sealldeveloper/CVE-2022-21661-PoC | POC Details |
| 10 | CVE-2022-21661 exp for Elementor custom skin. | https://github.com/guestzz/CVE-2022-21661 | POC Details |
| 11 | Script to validate WordPress CVE-2022-21661 | https://github.com/p4ncontomat3/CVE-2022-21661 | POC Details |
| 12 | None | https://github.com/CharonDefalt/WordPress--CVE-2022-21661 | POC Details |
| 13 | The first poc video presenting the sql injection test from ( WordPress Core 5.8.2-'WP_Query' / CVE-2022-21661) | https://github.com/safe3s/CVE-2022-21661 | POC Details |
| 14 | CVE-2022-21661 docker and poc | https://github.com/w0r1i0g1ht/CVE-2022-21661 | POC Details |
| 15 | None | https://github.com/kittypurrnaz/cve-2022-21661 | POC Details |
| 16 | WordPress before 5.8.3 is susceptible to SQL injection through multiple plugins or themes due to improper sanitization in WP_Query, An attacker can potentially obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-21661.yaml | POC Details |
| 17 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/WordPress%20WP_Query%20SQL%20%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E%20CVE-2022-21661.md | POC Details |
| 18 | A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment. | https://github.com/Fauzan-Aldi/CVE-2022-21661 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-21662 | 8.0 HIGH | Stored XSS in WordPress |
| CVE-2022-21664 | 7.4 HIGH | SQL injection in WordPress |
| CVE-2022-21663 | 6.6 MEDIUM | Authenticated Object Injection in Multisites in WordPress |
No comments yet